Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.27, 1.27-debian, 1.27-debian13, 1.27.3, 1.27.3-debian, 1.27.3-debian13

Index digest:

sha256:8fc181cf7d648ffdb30db3619859d904a4ae6a2058a03b1a10e233a351145adb

Manifest digest:

sha256:f7d941b2f3d82be3d69f0358658a41700d9385e941584605394d12084cdd74e4

Size

84.14 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
12
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:908c98e7f78bd7948ac400227369215668e6d31483734315161cf099d78d4f69
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:19136481cb072ecb0ff97375f53d2346981499394268dc82191680d351534be3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:18a0dd91b33b5b81b0ec4812fd0b0c7e49fe10aac91478dcbb1e8a92a10103a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:abba2c00187153ca0ee7cf929f2e31acda96443e47ca63a179e6830964029833
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:430e594a54dacff20d4bddfd2e32a428d0febe595609079323abbd67a797dcc1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:f127a47fda4c0819f8447d4d0676f68383442c595808b966f788afc62710c0ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:cf429c5bc8180f0950232bd6af1ea0b74c94d61f821ab6f6164c24d726e88153
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:3c7b6b5fa96cacef8f30fd2a173e0a23db4feedc41b5033f67dedd100eebae76
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:b27f6a75554d4c54741bd73c5ccd090807a7e09254e8801f0869dc8169c8b6fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:3889092bec23d991be0657b17d9656ef719e477a6fd728ca6a67701d7cfe812a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:09a45d927bcc142fab45347cbcd9f1bba532cb4eb08a1d71d13e069003a3adba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:01f5a72f33b25111aefdda557379607af7fbe97af817cc0dd2f6f76c091c339e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:e17125458f77fb65a1923d39a030ac82e30f6f514cc56365c1566eef398b7243
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:10acb5aafcec1f908a41a52a63ab0c78a5a14b63bfd9aeb5d52fd49a04b06b2b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:fa01df11d7d1e879096070bd4bf504c3272f7c70a658a0e8a2617bc1aafa416b